Windows 2008 R2 Event Log

Posted on 2012-08-30
Last Modified: 2012-08-30
2008 R2 64bit

I am in the process of defining a GPO on the default Domain controllers policy and I had enabled the following for audits:
1) Audit Logon Events (S/F) = Success and Failure
2) Account Management
3) Directory Service Access
4) Policy Change

I used best practice from MS to set the Max size for application, security and systems to 4194240 kb.

Now moving to the Retain and Retention, can anyone guide me on what would be best definied. I want to have the event there at least up to 90 days.
Question by:shoris
    LVL 6

    Accepted Solution

    I would select the option to overwrite events as needed.  The size you have set the log to (4GB) should be way more than sufficient to handle audits for 90 days.

    If you set anything else, people will be prevented from loggingin if the log fills up and you don't clear it.
    LVL 6

    Expert Comment

    by:Kiran Ch
    It would be a tricky answer. I would suggest you to plan for automatic archiving of eventlogs after certain number of days.

    Also there is another thread going on a similar topic. You can read it as well.

    Author Comment

    Thank you. So since I set it at 4gb and appled the retention override as needed, does that mean that if the log fills to 4gb then the retention will kick in and clear it. This way I don't have to clear it myself or risk of logs filled before any user can't login.
    LVL 6

    Expert Comment

    It will not clear the entire log.  It will "roll" the log, which means when you reach the 4GB mark, it will continue logging by replacing the oldest entry in the log first.  So if you write 5 entries, the oldest 5 entries will be lost.  Thereby we maintain the 4GB file size and still continue logging.

    Author Comment

    Thankyou so much for the explaination. Excellent. that works out.

    Featured Post

    Why do Marketing keep bothering you?

    Is your marketing department constantly asking for new email signature updates? Are they requesting a different design for every department? Do they need yet another banner added? Don’t let it get you down! There is an easy way to manage all of these requests...

    Join & Write a Comment

    Detailed instructions on how to install an Access add-in in recent versions of Office and Windows (with screen shots)
    Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
    Windows 8 came with a dramatically different user interface known as Metro. Notably missing from that interface was a Start button and Start Menu. Microsoft responded to negative user feedback of the Metro interface, bringing back the Start button a…
    With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

    755 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    23 Experts available now in Live!

    Get 1:1 Help Now